npm · weakspot-mcp
$npx -y weakspot-mcp@0.1.1 WEAKSPOT_PRIVATE_KEY · secret — Private key of a funded Base wallet. This server SPENDS REAL USDC from it with no human in the loop — use a fresh wallet funded with only what you are willing to lose, never a personal or deployer key. Only weakspot_audit needs it; the pricing, status and wallet-status tools work without one.
WEAKSPOT_MAX_USD — Hard cap in USD on any single audit (default 4, the highest tier). Checked twice: against the tier price, and again against the amount the server actually quotes. An LLM decides when to call the paying tool, so this is the main spend control.
WEAKSPOT_URL — Base URL of the Weakspot deployment to use. Defaults to https://weakspot.dev; override to point at staging or a self-hosted instance.
WEAKSPOT_RPC_URL — Base RPC endpoint, used only to read the wallet's USDC balance in weakspot_wallet_status. Nothing else needs it.